VulnSea

CWE-119

CVEs classified under CWE-119, newest first.

290 CVEsRSS

CVE-2026-13516High· 8.8
3mo ago

A vulnerability was detected in Tenda JD12L 16.03.53.23

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSpeed results in stack-based buffer over…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-13515High· 8.8
3mo ago

A security vulnerability has been detected in Tenda JD12L 16.03.53.23

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads to stack-based buffer overflow. The a…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-12329Medium· 5.3
3mo ago

Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

▾ Sunlitmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-12297Critical· 9.6
3mo ago

Sandbox escape due to incorrect boundary conditions in the Networking component

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Midnightmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-12292High· 8.1
3mo ago

Incorrect boundary conditions in the Web Audio component

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

▾ Twilightmozilla · firefoxEPSS 0.49%via NVD
CVE-2026-12290High· 8.1
3mo ago

Memory safety bug fixed in Firefox 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-10292High· 8.8
3mo ago

A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306

A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exp…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10125High· 8.8
4mo ago

A vulnerability was identified in Edimax BR-6478AC 1.23

A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-10124High· 8.8
4mo ago

A vulnerability was determined in Shibby Tomato up to 1.28

A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is p…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10123High· 8.8
4mo ago

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_lis…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10122High· 8.8
4mo ago

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflo…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-10121High· 8.8
4mo ago

A flaw has been found in TRENDnet TEW-432BRP 3.10B20

A flaw has been found in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. …

▾ TwilightEPSS 0.45%via NVD
CVE-2026-39830Critical· 9.1
4mo ago

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…

▾ Midnightgolang · cryptoEPSS 0.62%via NVD
CVE-2026-8975High· 8.8
4mo ago

Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150

Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary…

▾ Twilightmozilla · firefoxEPSS 0.59%via NVD
CVE-2026-8974High· 8.8
4mo ago

Memory safety bugs present in Firefox ESR 140.10 and Firefox 150

Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerab…

▾ Twilightmozilla · firefoxEPSS 0.45%via NVD
CVE-2026-8973High· 8.8
4mo ago

Memory safety bugs present in Firefox 150

Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Fire…

▾ Twilightmozilla · firefoxEPSS 0.46%via NVD
CVE-2026-8946High· 7.5
4mo ago

Incorrect boundary conditions in the Audio/Video: Web Codecs component

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

▾ Twilightmozilla · firefoxEPSS 0.60%via NVD
CVE-2026-8836Critical· 9.8PoC
4mo ago

A vulnerability was found in lwIP up to 2.2.1

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParamet…

▾ AbyssalEPSS 1.6%via NVD
CVE-2026-43658High· 7.5
4mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted…

▾ Twilightapple · ipadosEPSS 0.54%via NVD
CVE-2026-28990High· 7.5PoC
4mo ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. …

▾ Midnightapple · ipadosEPSS 0.52%via NVD
CVE-2026-8261Medium· 5.9
4mo ago

A vulnerability was determined in Squirrel up to 3.2

A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. Th…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-8260High· 8.8
4mo ago

A vulnerability was found in D-Link DCS-935L up to 1.10.01

A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword r…

▾ Twilightdlink · dcs-935l_firmwareEPSS 1.2%via NVD
CVE-2026-8258Medium· 5.3
4mo ago

A flaw has been found in Squirrel up to 3.2

A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The attack can only be executed locally. The…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-8234High· 8.8
4mo ago

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2

A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the argument security_5g leads to stack-based buffer …

▾ TwilightEPSS 0.80%via NVD
CVE-2026-39892Critical· 9.8⚖ disputed
5mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this …

▾ Midnightcryptography.io · cryptographyEPSS 0.76%via NVD
CVE-2026-5687High· 8.8
5mo ago

A weakness has been identified in Tenda CX12L 16.03.53.12

A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes stack-based buffer overflow. The attack m…

▾ Twilighttenda · cx12l_firmwareEPSS 0.99%via NVD
CVE-2026-5686High· 8.8
5mo ago

A security flaw has been discovered in Tenda CX12L 16.03.53.12

A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page results in stack-based buffer overflow. The at…

▾ Twilighttenda · cx12l_firmwareEPSS 0.99%via NVD
CVE-2026-5685High· 8.8
5mo ago

A vulnerability was identified in Tenda CX12L 16.03.53.12

A vulnerability was identified in Tenda CX12L 16.03.53.12. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated r…

▾ Twilighttenda · cx12l_firmwareEPSS 0.99%via NVD
CVE-2026-5684High· 8.0
5mo ago

A vulnerability was determined in Tenda CX12L 16.03.53.12

A vulnerability was determined in Tenda CX12L 16.03.53.12. Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to stack-based bu…

▾ Twilighttenda · cx12l_firmwareEPSS 0.69%via NVD
CVE-2026-5683Medium· 5.5
5mo ago

A vulnerability was found in Tenda CX12L 16.03.53.12

A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. Performing a manipulation of the argument page results in stack-based buffer overfl…

▾ Sunlittenda · cx12l_firmwareEPSS 0.63%via NVD
CWE-119 vulnerabilities (CVEs) — page 7 · VulnSea